Search:     Advanced search
server monitoring

Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)

Article ID: 11147
Last updated: 27 Jan, 2009
Views: 408
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyWindows : Microsoft Bulletins
Plugin ID11147
Bugtraq ID4387
5872
5874
CVE IDCVE-2002-0693
CVE-2002-0694

Description:

Synopsis :

Arbitrary code can be executed on the remote host through the web client.

Description :

The remote host contains a version of the HTML Helpfacility ActiveX control
module which is vulnerable to a security flaw which may allow an attacker
to execute arbitrary code on the remote host by constructing a malicious
web page and entice a victim to visit this web page.

Solution :

Microsoft has released a set of patches for Windows NT, 2000 and XP :

http://www.microsoft.com/technet/security/bulletin/ms02-055.mspx

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Vulnerability in Routing and Remote Access Could Allow Remote...     Trusting domains bad verification (Q311401)